ezcomments and $can_edit

Author Message

Pascal France

Wednesday 15 December 2010 2:53:21 pm

Hi,

I would like to know if it is possible to determine $can_edit in the template extension/ezcomments/design/standard/templates/comment/view/comment_item.tpl instead of in the template extension/ezcomments/design/standard/templates/comment/edit.tpl ?

I don't understand why the variable $can_edit is available at the top of the template edit.tpl (without any fetch) and not in comment_item.tpl

If this is possible so we can display the links «Edit» and «Delete» (to the bottom of each comment) only if the current user has these rights.

Currently, these 2 links are displayed at the bottom of each comment and we have to click on it to see if we can or not edit / delete the comment.

Ce qui embellit le désert c'est qu'il cache un puits... quelque part... (A. de Saint-Exupéry) - http://luxpopuli.fr/eZ-Publish

Pascal France

Thursday 16 December 2010 1:01:32 am

Hi,

When we are not allowed to edit a comment, an error message is displayed by the template

  • extension/ezcomments/design/standard/templates/comment/edit.tpl

once we have clicked the link «Edit» at the bottom of a comment.

This template does not display a "Back" button with the error message (as is the case with the template extension/ezcomments/design/standard/templates/comment/delete.tpl) and the user must return back to the previous page with the «Back» button of his browser.

I added a button with this code:

<form action={'/comment/edit'|ezurl} method="post" name="CommentEdit">
        <input type="hidden" name="CommentID" value="{$comment_id}" />
        <input type="hidden" name="RedirectURI" value={$redirect_uri|ezurl( , 'full' )} />
               <div class="message-error">
                  <p>
                     {'You don\'t have access to edit.'|i18n( 'ezcomments/comment/edit' )}
                  </p>
                <input type="submit" value="{'Back'|i18n( 'ezcomments/comment/action' )}" class="button" name="CancelButton" />
               </div>
            </form>

But the URL «{$redirect_uri|ezurl( , 'full' )}» refers to the root of the site and not to the previous page (which is the case with the template delete.tpl).

The problem I meet is that in the template edit.tpl no one of these variables is available:

  • $view_parameters
  • $ezhttp_hasvariable
  • $module_result.view_parameters
  • $module_result
  • $ezhttp_hasvariable
  • $node
  • $oject
  • $comment
  • $redirect_uri

So even if I pass the parameters in the URL I can not retrieve them.

Is there a way to have a button that returns to the previous page?

Ce qui embellit le désert c'est qu'il cache un puits... quelque part... (A. de Saint-Exupéry) - http://luxpopuli.fr/eZ-Publish

Daisy Radix

Thursday 16 December 2010 1:01:54 am

The tpl variable $canEdit is set in the extension/comments/module/comment/edit.php.(line 41)

$canEdit = false;
$canEditResult = ezcomPermission::hasAccessToFunction( 'edit', $contentObject, $languageCode, $comment, null, $contentNode );
$canEdit = $canEditResult['result'];
$tpl->setVariable( 'can_edit', $canEdit );

If you want this variable in comment_item.tpl you can override it and add a fetch permission at the top of the tpl file.

eZ Publish certified developper :http://auth.ez.no/certification/verify/378142

Pascal France

Thursday 16 December 2010 1:41:30 am

Hi Daisy,

And thanks for your help.

In comment_item.tpl there are already, by default, a «can_edit» and a «can_detele» fetch. But they always return «false» .

In comment_item.tpl the only variables that change according to the permissions of the user are "$can_self_edit" and "$can_self_delete".

The problem is that you can be a user logged in with permission can_self_edit and not have the right to edit the comment of another user.
It seems that this case can not be taken into account in comment_item.tpl

Ce qui embellit le désert c'est qu'il cache un puits... quelque part... (A. de Saint-Exupéry) - http://luxpopuli.fr/eZ-Publish

Daisy Radix

Thursday 16 December 2010 2:34:29 am

I don't really understand what you want to do if the user can't edit the comment there's no edit button and if he can there's one.

Have you an example to illustrate your situation?

eZ Publish certified developper :http://auth.ez.no/certification/verify/378142

Pascal France

Thursday 16 December 2010 2:59:08 am

Daisy, I sent you a private mail (from here this page http://share.ez.no/authorcontact/form/95875).

Ce qui embellit le désert c'est qu'il cache un puits... quelque part... (A. de Saint-Exupéry) - http://luxpopuli.fr/eZ-Publish

Pascal France

Friday 17 December 2010 2:48:31 am

I explain again the context:

By default, the extension ezcomments displays the links "Edit" and "Delete" at the bottom of all comments regardless of the specific rights of the user.

My original question (see my first post) was: how to display the links "Edit" and "Delete" only if the user has the right to edit and/or delete the comment ?

Daisy founded the solution:

We have to replace (in comment_item.tpl):

<div class="ezcom-comment-tool">
                    {if or( $can_edit, $can_self_edit )}
                        {if and( $can_self_edit, not( $can_edit ) )}
                            {def $displayAttribute=$user_display_limit_class}
                        {else}
                            {def $displayAttribute=''}
                        {/if}
                        <span{$displayAttribute}>
                            <a href={concat( '/comment/edit/', $comment.id )|ezurl}>{'Edit'|i18n('ezcomments/comment/view')}</a>
                        </span>
                        {undef $displayAttribute}
                    {/if}
                    {if or( $can_delete, $can_self_delete )}
                        {if and( $can_self_delete, not( $can_delete ) )}
                            {def $displayAttribute=$user_display_limit_class}
                        {else}
                            {def $displayAttribute=''}
                        {/if}
                        <span {$displayAttribute}>
                            <a href={concat( '/comment/delete/',$comment.id )|ezurl}>
                                {'Delete'|i18n('ezcomments/comment/view')}
                            </a>
                        </span>
                        {undef $displayAttribute}
                    {/if}
                </div>

by:

{if eq( $current_user.contentobject_id, $comment.user_id )}
                  <span {$displayAttribute}>
                     <a href={concat( '/comment/edit/', $comment.id )|ezurl}>{'Edit'|i18n('ezcomments/comment/view')}</a>  
                     <a href={concat( '/comment/delete/',$comment.id )|ezurl}>{'Delete'|i18n('ezcomments/comment/view')}</a>
                  </span>
                  {undef $displayAttribute}
               {/if}

Like that, the «Edit» and «Delete» buttons are only shown if the logged in user is the owner of the comment too.

More over, this solution avoids to solve the problem I described in my 2de post of this thread.

Ce qui embellit le désert c'est qu'il cache un puits... quelque part... (A. de Saint-Exupéry) - http://luxpopuli.fr/eZ-Publish

Chen Xiongjie

Friday 21 January 2011 2:11:18 am

Pascal, for the 1st issue, have you tried to configure it like this?

Go to administrator user interface, in the user role interface -> click 'add policy' -> select module 'comment' and function 'edit' -> click 'grant limited access' -> select 'Self' in CommentCreator.

Documentation: http://doc.ez.no/Extensions/eZ-Comments/Setup-and-user-guide-1.1/Using-eZ-Comments/Adminstrator-options/Setting-access-and-restriction-policies

(Sorry for the late reply)

eZ Comments: http://projects.ez.no/ezcomments
twitter: http://twitter.com/xiongjie

Chen Xiongjie

Friday 21 January 2011 2:35:14 am

Just one note for 2nd issue: since comment edit view is not like ezpublish object edit view, the parameters in object are not available. And there is no object/node parameter here at all. But you can retrive them manually via comment id, see modules/comment/edit.php where there is example.

(Of course if 1st is solved, you don't need to think about 2nd).

eZ Comments: http://projects.ez.no/ezcomments
twitter: http://twitter.com/xiongjie

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 18 2025 03:10:51
Script start
Timing: Jan 18 2025 03:10:51
Module start 'layout'
Timing: Jan 18 2025 03:10:51
Module start 'content'
Timing: Jan 18 2025 03:10:51
Module end 'content'
Timing: Jan 18 2025 03:10:51
Script end

Main resources:

Total runtime0.0139 sec
Peak memory usage2,048.0000 KB
Database Queries3

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0047 589.0234152.6250
Module start 'layout' 0.00470.0031 741.648439.4531
Module start 'content' 0.00780.0042 781.1016106.0547
Module end 'content' 0.01200.0019 887.156346.2891
Script end 0.0139  933.4453 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.002316.3121140.0002
Check MTime0.00107.4596140.0001
Mysql Total
Database connection0.00064.471610.0006
Mysqli_queries0.002719.286430.0009
Looping result0.00000.094110.0000
Template Total0.001611.410.0016
Template load0.00096.116210.0009
Template processing0.00075.233210.0007
Override
Cache load0.00064.285110.0006
General
dbfile0.00031.867080.0000
String conversion0.00000.035940.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 1
 Number of unique templates used: 1

Time used to render debug report: 0.0001 secs